GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.
{ "binaries": [ { "binary_version": "1.7+dfsg-4", "binary_name": "rush" } ], "availability": "No subscription required" }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-6889.json"
{ "binaries": [ { "binary_version": "1.7+dfsg-4", "binary_name": "rush" }, { "binary_version": "1.7+dfsg-4", "binary_name": "rush-dbgsym" } ], "availability": "No subscription required" }